omh-jit-learn
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill instructions define a legitimate research workflow focused on learning target selection and source-gated recommendations.\n- [SAFE]: No obfuscation techniques, such as Base64 encoding, zero-width characters, or homoglyph attacks, were detected. The non-English text in the routing signals consists of valid Korean translations relevant to the skill's purpose.\n- [SAFE]: No hardcoded credentials, sensitive file access, or suspicious network operations were found in the skill definitions.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied learning goals and external source data, presenting an attack surface for indirect prompt injection. This is evaluated as safe due to the implementation of robust internal controls.\n
- Ingestion points: User prompts and external source research results are the primary data inputs.\n
- Boundary markers: The protocol mandates an explicit target confirmation step ("Learn X now so I can do/decide Y...") and a 6-round interview ceiling to prevent drifting into unintended instructions.\n
- Capability inventory: The skill uses the
omhCLI for runtime recording; it does not define additional file system or network tools that could be abused.\n - Sanitization: The skill employs mandatory confirmation questions and strict source-gating criteria that prioritize authority and fit over generic popularity signals.
Audit Metadata